← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mattermost
1Mattermost Server
Jun 17, 2026
Feb 29, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access indi...Show more
Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels they are not a member of. Show less
1Mattermost
1Mattermost Server
Jun 17, 2026
Feb 29, 2024
N/A· v4
2.6 LOW· v3
N/A· v2
A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while anothe...Show more
A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while another user deletes posts. Show less
1Mattermost
1Mattermost Server
Jun 17, 2026
Feb 29, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of. 
1Tainacan
1Tainacan
Jun 17, 2026
Feb 29, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Insertion of Sensitive Information Into Sent Data vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.20.6.
1Fullstackhero
1.net 9 Starter Kit
Jun 17, 2026
Feb 29, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request.
1Element
1Element
Jun 17, 2026
Feb 29, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Element Android is an Android Matrix Client. A third-party malicious application installed on the same phone can force Element Android, version 0.91.0 through 1.6.12, to share files stored under the `files` directory in...Show more
Element Android is an Android Matrix Client. A third-party malicious application installed on the same phone can force Element Android, version 0.91.0 through 1.6.12, to share files stored under the `files` directory in the application's private data directory to an arbitrary room. The impact of the attack is reduced by the fact that the databases stored in this folder are encrypted. However, it contains some other potentially sensitive information, such as the FCM token. Forks of Element Android which have set `android:exported="false"` in the `AndroidManifest.xml` file for the `IncomingShareActivity` activity are not impacted. This issue is fixed in Element Android 1.6.12. There is no known workaround to mitigate the issue.Show less
1Couchbase
1Couchbase Server
Jun 17, 2026
Feb 29, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.
1Passwordprotectwp
1Password Protect Wordpress
Jun 17, 2026
Feb 29, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. This makes it possible for unauthenticated attackers to obtain p...Show more
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. This makes it possible for unauthenticated attackers to obtain post titles, IDs, slugs as well as other information including for password-protected posts.Show less
1Wpchill
1Passster
Jun 17, 2026
Feb 29, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 via API. This makes it possible for unauthenticated att...Show more
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 via API. This makes it possible for unauthenticated attackers to obtain post titles, slugs, IDs, content and other metadata including passwords of password-protected posts and pages.Show less
1Acurax
1Under Construction / Maintenance Mode
Jun 17, 2026
Feb 28, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.6 via the 'acx_csma_subscribe_ajax' function. This can allow...Show more
The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.6 via the 'acx_csma_subscribe_ajax' function. This can allow authenticated attackers to extract sensitive data such as names and email addresses of subscribed visitors.Show less
1Rubyonrails
1Rails
Jun 17, 2026
Feb 27, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's sess...Show more
Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak. The vulnerability is fixed in 7.0.8.1 and 6.1.7.7.Show less
1Apache
1Aurora
Jun 17, 2026
Feb 27, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing internals to unauthenticated users can be used as a "padding oracle" allowi...Show more
** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing internals to unauthenticated users can be used as a "padding oracle" allowing an anonymous attacker to construct a valid authentication cookie. Potentially this could be combined with vulnerabilities in other components to achieve remote code execution. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.Show less
1Gl Inet
26A1300 Firmware
Ar300m16 FirmwareAr300m Firmware+23 more
Jun 17, 2026
Feb 27, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5.5, XE3000 4.4.4, X3000 4.4.5, MT3000 4....Show more
An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5.5, XE3000 4.4.4, X3000 4.4.5, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, XE300 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-v2 4.3.10, X300B 3.217, S1300 3.216, SF1200 3.216, MV1000 3.216, N300 3.216, B2200 3.216, and X1200 3.203.Show less
1Innovaphone
1Innovaphone Pbx
Jun 17, 2026
Feb 27, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists on a system.
1Rylabs
1Rack Cors Middleware
Jun 17, 2026
Feb 26, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.
1Wiloke
1Myshopkit
Jun 17, 2026
Feb 26, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiloke WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit.This issue affects WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit: fro...Show more
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiloke WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit.This issue affects WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit: from n/a through 1.0.9.Show less
2Apostrophecms
Fedoraproject
2Fedora
Sanitize Html
Jun 17, 2026
Feb 24, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dep...Show more
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.Show less
1Ecomiz
1Survey Tma
Jun 17, 2026
Feb 23, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In the module "Survey TMA" (ecomiz_survey_tma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download personal information without restriction.
1Intel
4Ethernet Adapter Complete Driver
Ethernet Controller I225 It FirmwareEthernet Controller I225 Lm Firmware+1 more
Jun 17, 2026
Feb 23, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticated user to potentially enable information disclosure via network access.
1Enalean
1Tuleap
Jun 17, 2026
Feb 22, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.5.99.76 of Tuleap Community Edition and prior to versions 15.5-4 and 15.4-7 of Tuleap Enterprise Editio...Show more
Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.5.99.76 of Tuleap Community Edition and prior to versions 15.5-4 and 15.4-7 of Tuleap Enterprise Edition, users with a read access to a tracker where the mass update feature is used might get access to restricted information. Tuleap Community Edition 15.5.99.76, Tuleap Enterprise Edition 15.5-4, and Tuleap Enterprise Edition 15.4-7 contain a patch for this issue.Show less